US2018293367A1PendingUtilityA1

Multi-Factor Authentication via Network-Connected Devices

Assignee: GOOGLE LLCPriority: Apr 5, 2017Filed: Mar 1, 2018Published: Oct 11, 2018
Est. expiryApr 5, 2037(~10.7 yrs left)· nominal 20-yr term from priority
Inventors:Andrew Urman
G10L 17/005H04L 63/0861G06F 21/32G10L 17/22G06N 99/005H04L 67/10G06K 9/00288G06F 21/316G06V 40/20G06V 40/172G06V 20/44G06N 20/00G10L 17/00H04W 4/70H04L 67/12H04W 12/06H04L 2463/082H04L 41/06H04L 41/22
37
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Multi-factor authentication via network-connected devices is described, and techniques provide for generating and utilizing behavioral authentication factors for multi-factor authentication of user identities. Behavioral authentication factors are learned by training models, using machine learning techniques, from user behaviors sensed by network-connected devices and monitored by a service. A system for multi-factor authentication via network-connected devices receives indications of user activity from network-connected devices and detects a pattern of activity that is compared to the behavioral authentication factor to determine a confidence level that the pattern of activities matches the behavioral authentication factor, and authenticates the user identity if the confidence level exceeds a threshold for authentication of the user identity.

Claims

exact text as granted — not AI-modified
1 . A system for generating a behavioral authentication factor, the system comprising:
 a service configured to:
 receive indications of user activity from multiple network-connected devices that are monitored by the service; 
 compose a training dataset from the received indications; and 
 generate the behavioral authentication factor by training a model using the training dataset. 
   
     
     
         2 . The system of  claim 1 , wherein the received indications include sensor readings, control commands, user interactions, or any combination thereof from the network-connected devices. 
     
     
         3 . The system of  claim 2 , wherein the received indications include user location information. 
     
     
         4 . The system of  claim 1 , wherein the training dataset includes structure resource data or external resource data. 
     
     
         5 . The system of  claim 4 , wherein the structure resource data includes aggregations of traits of the network-connected devices in a structure that are useful in providing services, information related to users and user accounts that are associated with various services provided in relation to the structure, and a home graph that describes connections and relationships between the network-connected devices, elements of the structure, and users. 
     
     
         6 . The system of  claim 4 , wherein the external resource data includes data from partner cloud services, calendaring services, email services, news services, weather services, or location-based services for mobile devices. 
     
     
         7 . The system of  claim 1 , further comprising a user authentication service configured to determine an authentication confidence level using the generated behavioral authentication factor. 
     
     
         8 . A method for authenticating a user identity based on a behavioral authentication factor, the method comprising:
 receiving, at a service, indications of user activity from multiple network-connected devices that are monitored by the service;   detecting a pattern of activities in the received indications of user activity;   comparing the pattern of activities to the behavioral authentication factor;   determining a confidence level that the pattern of activities corresponds to the behavioral authentication factor; and   authenticating the identity of the user if the determined confidence level exceeds a threshold value for authentication of the identity of the user.   
     
     
         9 . The method of  claim 8 , wherein the determining the confidence level includes determining the confidence level that the pattern of activities matches the behavioral authentication factor. 
     
     
         10 . The method of  claim 8 , wherein the behavioral authentication factor is a model of user behavior, and wherein the model of user behavior is generated by training a machine learning algorithm with user activities received from the network-connected devices and monitored by the service. 
     
     
         11 . The method of  claim 10 , wherein the network-connected devices include a security sensor, a camera, a thermostat, a motion sensor, a light switch, a user device, a smart speaker, or any combination thereof. 
     
     
         12 . The method of  claim 8 , wherein when the detected pattern of activities does not match a learned pattern of behaviors a notification is sent to the user. 
     
     
         13 . The method of  claim 12 , wherein the notification is sent to the user device by the service. 
     
     
         14 . The method of  claim 8 , wherein the received indications of user activity include location information for the user. 
     
     
         15 . A system to authenticate a user identity based on a user's passive or active interactions with network-connected devices, the system comprising:
 a user authentication service configured to:
 receive an indication of a user identity; 
 determine a device, of the network-connected devices associated with the user identity, for a user interaction; 
 request the user interaction via the device; 
 monitor the device to receive an indication of the user interaction with the device; and 
 based on the received indication of the user interaction, authenticate the identity of the user. 
   
     
     
         16 . The system of  claim 15 , wherein to determine the device, the user authentication service is configured to determine a predetermined network-connected device, and the predetermined network-connected device is known to the authentication service and to the user. 
     
     
         17 . The system of  claim 16 , wherein the network-connected devices are disposed about a structure, and wherein the authentication indicates the user is authorized to access to the structure. 
     
     
         18 . The system of  claim 15 , wherein to determine the device for the user interaction, the user authentication service is configured to select the device from the network-connected devices that are associated with the user identity, and wherein the indication of the user interaction includes an identification of the determined device. 
     
     
         19 . The system of  claim 15 , wherein the network-connected devices include a motion sensor, a security sensor, a thermostat, a camera, a smart speaker, or a light switch. 
     
     
         20 . The system of  claim 15 , wherein the requested user interaction is facial recognition and the device is a camera, or wherein the requested user interaction is voice recognition and the device is a smart speaker.

Join the waitlist — get patent alerts

Track US2018293367A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.